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1 . A computer-implemented method comprising: 

detecting a data signature hy evaluating communications at, an application lay e r 

level between a target and a susoect: [[and]] 

correlating said data signature with an application layer fingerprint of the target to 
determine to what extent said target is vulnerable to said data signature^and 

O pting contextual informati on related to the data signature to determine^ 
livelihood that g»M target is und e r attack, the contextual information comprising , at least one of 
an annlication W data field t v ne used to encapsulate the data nipnaturc and m application 
laver protocol type used to transmit the data signature. 

14. A computer-implemented method comprising: 

identifying a data signature encapsulated in an application laver data field and 
directed at a target using an app lication layer protocol; 

evaluating said a context of the data signature[['s]] oontoxt by one o ft 
com paring the data signature t o the application laver data fiejdi 
com parine the data signature t o the application laver protocol: and 
determining whether said data signature poses a threat based on said context of 
said data signature. 
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25 . A ^y^tftr-im plemented method comprising: 

monitoring a plurality of data transmissions it an applications layer level between 
a suspect and a target ™ « more data signature said data transmissions indicating a 

current state of communication between said suspect and said target; 

^i ^tino contextual information ~l a tert to each data denature, the contextual 
in*™**™ compri ci ^ * least one of an plication layer data field , type used to encapsulate a 
r ^tive data ^ ™H an appli ed lavcr nrotocol type used to transmit a respective da^a 
signature; and 

evaluating a likelihood that said target is under attack based on the contextua l 
information of one or more data signatures of said transmissions and said current state of 
communication. 

37. A machine-readable medium having program code stored thereon which, 
when executed by a machine, causes said machine to perform the operations of: 

detecting a data signature bv evaluating fl ornmiinications at an application layer 
level between a target and a suspect: [[and]] 

correlating said data signature with a fingerprint of the target to determine to what 
extent said target is vulnerable to said data signatureund 

evaluating contextual inform ation related fo the data signature to determine^ 
likelihood that ffH target is under attack - th e cnntextual information comprising at least one of 
an application laver data field type used to encapsulate the data signature and an application 
jayer protocol type used to transmit the data signature . 
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50. A machine-readable medium having program code stored thereon which, 
when executed by a machine, causes said machine to perform the operations of: 

identifying a data signature insulated in an application layer data field directed 

at a target using an app lication laver protocpj; 

evaluating M » context of the data signature[['s]] <***e*t by one of: 
™mn*rin p the data «f matiire to th? ap plication laveT data fidft 
s naring the data rip nupue to the application layer protocol; and 
determining whether said data signature poses a threat based on said context of 
said data signature. 

56. A machine-readable medium having program code stored thereon which, 
when executed by a machine, causes said machine to perform the operations of: 

monitoring a plurality of data transmissions at_an applicator* layer level between 
a suspect and a target ^ntifV one or more data signatures, said data transmissions indicating a 
current state of communication between said suspect and said target; 

» Y?hi**in e conte vt,^ informati o n related to each data signature, the context 
information comprising a t least or »r "f »" ^cation laver data field tynfl used to encapsulate a 
rff paetiv data g i r «tnre and an an pl^tinn laver protocol type used to transit « respective data 
signature: and 

evaluating a likelihood that said target is under attack based on the coptextual 
information of one or more data signatures of said transmissions and said current state of 
communication. 
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